Bug Bounty
Sanad welcomes good-faith security research that helps protect Software Engineers using our account flow, business workspaces, billing, API access, session timer, and AI access controls.
One free testing week. Create a Sanad test account, then email support@sanad.dev with that account email and your testing plan to request the free testing week. Create a Sanad account.
Scope
The current in-scope Sanad properties are sanad.dev, www.sanad.dev, app.sanad.dev, id.sanad.dev, api.sanad.dev, and ai.sanad.dev. Eligible research includes sign-in and registration flows, account and business authorization boundaries, billing and balance boundaries, API key handling, session start/stop behavior, daily usage limits, rate limits, AI access controls, public pages, and admin surfaces when tested only with accounts you control.
Rewards
Rewards are issued as Sanad access credit after paid access is available. We assign severity based on demonstrated business and user impact, exploitability, affected users, and the quality of the report.
Severity guide
Critical
Examples include reliable unauthorized access to another user's registration data, account data, API key material, or AI access; taking over another account; performing admin-only activation or revocation actions without authorization; or a vulnerability that exposes sensitive user data at scale.
High
Examples include bypassing account, balance, business, or session checks to use Sanad AI; the ability to keep an AI session active while the usage timer is not charged; materially extending daily usage without authorization; modifying another user's access status; or accessing another user's limited profile or usage information.
Medium
Examples include account or session weaknesses that require user interaction, cross-site scripting with meaningful account impact, rate-limit bypasses that create measurable service abuse, improper access to non-sensitive metadata, or workflow flaws that let a user gain limited extra paid access or balance benefit.
Low
Examples include low-impact security header issues, low-risk open redirects, self-contained client-side issues, information disclosure that does not expose personal data or secrets, or UI flaws that could mislead a user without changing access or usage records.
Safe testing rules
- Use only registered test accounts and API keys you control.
- Keep testing targeted, low volume, and limited to proof needed for reproduction.
- Stop testing and report immediately if you access data that is not yours.
- Do not persist, modify, delete, or exfiltrate another user's data.
- Do not attempt social engineering, phishing, physical attacks, spam, denial-of-service testing, or high-volume automated scanning.
- Do not attack Google, Microsoft, Cloudflare, model providers, payment providers, banks, or other third-party systems.
- Do not publicly disclose a vulnerability before Sanad confirms remediation or provides written permission.
How to report
Send reports to support@sanad.dev. Include a short title, affected URL or surface, the account email used for testing, clear reproduction steps, expected and actual behavior, security impact, screenshots or screen recordings when useful, and any logs needed to reproduce the issue. Remove secrets, raw tokens, unrelated personal data, and third-party confidential information from the report.
Eligibility and exclusions
Eligible reports must be original, reproducible, affect an in-scope Sanad property, and show a concrete security impact. The first clear report of a duplicate issue is eligible. Out-of-scope findings include missing best-practice headers without exploitability, clickjacking on non-sensitive public pages, reports based only on automated scanner output, leaked credentials from systems Sanad does not control, account enumeration without impact, spam or availability-only testing, and issues requiring access to another person's account, device, mailbox, or browser.
Good-faith research
If you follow this policy and act in good faith, Sanad will treat your research as authorized for the in-scope Sanad systems. This authorization does not apply to third-party services or activity that violates the safe testing rules.
Contact
For questions about scope, testing access, or an active report, contact support@sanad.dev.